Aplicación fraudulenta para iPhone escapa del sandbox de iOS para secuestrar 580.000 dólares en USDT
Story summary
Fomopeek, una aplicación maliciosa para iPhone distribuida a través de la App Store de Apple, ha sido vinculada a casi 580.000 dólares en USDT robados. La empresa de seguridad Blockchain SlowMist comenzó a investigar la aplicación durante el fin de semana después de recibir informes de activos robados vinculados a claves privadas expuestas. Algunas víctimas tenían antecedentes
📌 Key Highlights & Takeaways
- Fomopeek, una aplicación maliciosa para iPhone distribuida a través de la App Store de Apple, ha sido vinculada a casi 580.000 dólares en USDT robados.
- La empresa de seguridad Blockchain SlowMist comenzó a investigar la aplicación durante el fin de semana después de recibir informes de activos robados vinculados a claves privadas expuestas.
- Algunas víctimas tenían antecedentes
Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT.
Blockchain security firm SlowMist began investigating the app over the weekend after receiving reports of stolen assets linked to exposed private keys.
Some victims had previously installed versions 1.1 or 1.2 of the Fomopeek app, which was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron.
Working with security researchers at crypto exchange OKX, SlowMist found two modules embedded in those versions that had no connection to FomoPeek’s advertised monitoring functions.
One communicated with external command-and-control infrastructure, while the other contained a kernel exploitation framework with eight attack methods that could adjust to the victim’s iPhone model and operating-system version.
A successful exploit could escape Apple’s application sandbox and reach Keychain information and files belonging to other apps. That created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.
SlowMist founder Yu Xian said the risk extended to passwords stored in Apple’s Keychain and encrypted files held by other applications. An attacker who obtained both could potentially unlock wallet credentials and other sensitive information stored on the device.
“After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”
Crypto Profit & Yield Calculator
Simulate trading returns, staking APY, and crypto gains with real-time fee modeling.
Source: CryptoSlate.
On-Chain Whale Radar: Smart Money Cold Wallet Outflows & High-Yield DeFi Opportunities
Uncover high-yield crypto alpha, on-chain whale accumulation alerts, 100x altcoin gems, and automated DeFi yield opportunities before the retail crowd.
Track Whale Wallets ➔💎 On-Chain Wallet Tracking & Breakout Targets
Direct wallet address monitoring, smart money flows, and liquidity depth.
⚡ Track Whale Wallets Now ➔